Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How XBOW Found a Scoold Authentication Bypass

Summary

XBOW's autonomous auth bypass in Scoold, the open-source Q&A platform: unauthenticated attackers could read or modify the instance config and, via HOCON quirks, read arbitrary files on the host.
Published
Collected

original ↗

Related coverage

back